HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLowContained
DocketWise
bd_b7206884fd165144 · schema v1 · pii pii-v1
Full breach record for DocketWise →DocketWise, an immigration and case management software provider, notified the California AG of a security incident where an unauthorized actor used valid credentials to clone third-party partner repositories used in its data migration pipeline. The incident was suspected in October 2025. Affected data included names and other personal information of clients of immigration law firms. DocketWise engaged forensic experts, notified the FBI, and is offering credit monitoring.
California clockDiscovered Oct 1, 2025 → Notified Apr 3, 2026184d ✗ CA 60-day late30 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_40e1c71041a9a978New Hampshire State AGfiled 2026-05-01Verified
- bd_1f933422ef9106ceMaine State AGfiled 2026-05-22(21d gap)Verified
- bd_14c2b0dfc72d503eWashington State AGfiled 2026-04-03(28d gap)Candidate
- bd_19d49447e198e5e8New Hampshire State AGfiled 2026-04-03(28d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 28d gap
- bd_270698bf44ac9aafMaine State AGfiled 2026-04-03(28d gap)Verified
- bd_db21719c17d2f149Vermont State AGfiled 2026-04-03(28d gap)Verified
- bd_e285f2bea7e3adc5Indiana State AGfiled 2026-04-03(28d gap)Verified by operator
- bd_f56df3950ca029eeCalifornia State AGfiled 2026-04-03(28d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-622723
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- dad16817f09b2e3dc2fb8972173b7659ee036abb9ef1f5f667d037bb814cd65e
Reporting entity
- Name
- DocketWisenorm: docketwise
- Domain
- app.docketwise.com
Victim entity
- Name
- DocketWisenorm: docketwise
- Domain
- app.docketwise.com
Incident
- Discovered
- Oct 1, 2025
- Materiality determined
- —
- Notification sent
- Apr 3, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation (FBI)
- Initial access
- supply_chain
Compliance
- Time to disclose
- 30 weeks(212 days from discovery to filing)
- Compliance flags
- CA 60-day late · 184dCA AG copy >15d · 28d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 1, 2025→ Notified: Apr 3, 2026184d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Apr 3, 2026→ AG copy submitted: May 1, 202628d 15 calendar days CA AG copy >15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.